Vulnerability Description
Zoho ManageEngine Applications Manager 12 through 14 allows FaultTemplateOptions.jsp resourceid SQL injection. Subsequently, an unauthenticated user can gain the authority of SYSTEM on the server by uploading a malicious file via the "Execute Program Action(s)" feature.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zohocorp | Manageengine Applications Manager | >= 12.0, <= 14.0 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/152607/ManageEngine-Applications-Manager-14ExploitThird Party AdvisoryVDB Entry
- https://pentest.com.tr/exploits/ManageEngine-App-Manager-14-Auth-Bypass-Remote-CExploitThird Party Advisory
- https://www.exploit-db.com/exploits/46740ExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/46740/ExploitThird Party AdvisoryVDB Entry
- https://www.manageengine.com/products/applications_manager/security-updates/secuVendor Advisory
- http://packetstormsecurity.com/files/152607/ManageEngine-Applications-Manager-14ExploitThird Party AdvisoryVDB Entry
- https://pentest.com.tr/exploits/ManageEngine-App-Manager-14-Auth-Bypass-Remote-CExploitThird Party Advisory
- https://www.exploit-db.com/exploits/46740ExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/46740/ExploitThird Party AdvisoryVDB Entry
- https://www.manageengine.com/products/applications_manager/security-updates/secuVendor Advisory
FAQ
What is CVE-2019-11469?
CVE-2019-11469 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Zoho ManageEngine Applications Manager 12 through 14 allows FaultTemplateOptions.jsp resourceid SQL injection. Subsequently, an unauthenticated user can gain the authority of SYSTEM on the server by u...
How severe is CVE-2019-11469?
CVE-2019-11469 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-11469?
Check the references section above for vendor advisories and patch information. Affected products include: Zohocorp Manageengine Applications Manager.